Mutable Protection Domains: Towards a Component-Based System for Dependable and Predictable Computing

Mutable Protection Domains: Towards a Component-Based System for Dependable and Predictable Computing
复制标题

DOI:
10.1109/rtss.2007.27
复制
发表时间:
2007-12
期刊:
28th IEEE International Real-Time Systems Symposium (RTSS 2007)
影响因子:
--
通讯作者:
Gabriel Parmer;R. West
Gabriel Parmer;R. West
中科院分区:
其他
文献类型:
--
作者:
Gabriel Parmer;R. West

文献摘要

被引文献

相似文献

软件的日益复杂性对实时和嵌入式系统提出了重大挑战,超越了纯粹基于时效性的系统。随着嵌入式系统和应用程序在从移动的电话、PDA到汽车、飞机等各种设备上运行,一个新出现的挑战是确保复杂软件的功能和时序正确性。我们认为,软件的静态分析是不足以验证所有可能的控制流交互的安全性。类似地,静态系统结构(软件可以在其上被隔离在单独的保护域中,从而在系统和应用级代码之间定义不可变的边界)对于具有明确定时要求的实时应用所面临的挑战来说太不灵活。因此,本文研究了一个概念,称为“可变保护域”,支持的概念,硬件自适应的软件组件之间的隔离边界。通过这种方式,可以动态地重新配置系统以最大化软件故障隔离,提高可靠性,同时保证根据特定的时间约束执行各种任务。使用一系列的多维,多选择背包问题的模拟,我们展示了如何比较各种不同的算法在他们的能力,快速重组的故障隔离边界的组件为基础的系统,以确保资源的限制,同时最大限度地提高隔离效益。我们的ssh oneshot算法提供了一种很有前途的方法来解决系统动态,包括改变组件调用模式,改变执行时间,以及由于缓存等因素而导致的隔离成本的预测错误。
The increasing complexity of software poses significant challenges for real-time and embedded systems beyond those based purely on timeliness. With embedded systems and applications running on everything from mobile phones, PDAs, to automobiles, aircraft and beyond, an emerging challenge is to ensure both the functional and timing correctness of complex software. We argue that static analysis of software is insufficient to verify the safety of all possible control flow interactions. Likewise, a static system structure upon which software can be isolated in separate protection domains, thereby defining immutable boundaries between system and application-level code, is too inflexible to the challenges faced by real-time applications with explicit timing requirements. This paper, therefore, investigates a concept called "mutable protection domains" that supports the notion of hardware-adaptable isolation boundaries between software components. In this way, a system can be dynamically reconfigured to maximize software fault isolation, increasing dependability, while guaranteeing various tasks are executed according to specific time constraints. Using a series of simulations on multidimensional, multiple-choice knapsack problems, we show how various heuristics compare in their ability to rapidly reorganize the fault isolation boundaries of a component- based system, to ensure resource constraints while simultaneously maximizing isolation benefit. Our ssh oneshot algorithm offers a promising approach to address system dynamics, including changing component invocation patterns, changing execution times, and mispredictions in isolation costs due to factors such as caching.